logo

ConnectWise breached in cyberattack linked to nation-state hackers

ID: 48b09039-ec6d-58f9-a147-f7c15d4e9902

STIX ID: report--48b09039-ec6d-58f9-a147-f7c15d4e9902

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-05-29

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

ConnectWise reported suspicious activity it believes was tied to a sophisticated nation-state actor that impacted a very small number of cloud-hosted ScreenConnect customers; the company engaged Mandiant, coordinated with law enforcement, implemented enhanced monitoring and mitigations, and patched a high-severity ASP.NET ViewState deserialization vulnerability (CVE-2025-3935) that could allow remote code execution, though details on exploitation, affected customers, and IOCs remain scarce.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.